iOS APN profile installation fails on supervised iPad with MDM restrictionsSolved

Participant
Discussion
1 day ago Sep 28, 2026

An enrolled iPad needed a carrier APN profile to activate cellular service. The APN profile was provided as a file from the carrier, so the plan was to download it on the iPad, open it, and install it manually.

When the Hexnode policy was applied, iPadOS showed that profile installation through the UI was disabled. I then enabled the restriction setting that allows installing configuration profiles, but the manual install still failed with another profile installation error.

The only workaround that worked was removing the Hexnode policy, installing the carrier APN profile manually, and then pushing the policy back to the iPad. Is there a better way to handle carrier APN profiles without removing the MDM policy each time?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
1 day ago Sep 28, 2026
Marked SolutionPending Review

Hi @maevee ,

This happens because iOS handles manual configuration profile installation differently on supervised, MDM-managed devices. Even if the restriction to allow configuration profile installation is enabled, manually installing a carrier-provided APN profile through the iPad UI can still run into iOS profile management restrictions or conflicts with enforced MDM policies.

The recommended approach is to deploy the APN through Hexnode instead of asking users to install the profile manually. This avoids the profile installation UI entirely and allows the APN to be installed silently over the air.

You can use either of these methods:

1. Configure the APN payload in Hexnode

  • Go to Policies.
  • Create or edit an iOS policy.
  • Navigate to Network > APN.
  • Enter the APN details provided by the carrier.
  • Save the policy and assign it to the iPad.

2. Deploy the carrier .mobileconfig file as a custom configuration

  • Go to Policies > iOS > Configurations > Deploy Custom Configuration.
  • Upload the carrier-provided .mobileconfig file.
  • Save the policy and assign it to the required iPad.

If the carrier has provided a ready-made APN .mobileconfig file, the second method is often the easiest option. Hexnode will install it as a managed configuration profile, without requiring the user to open and install it manually on the device.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
1 day ago Sep 28, 2026
Marked SolutionPending Review

So enabling “Install configuration profile” under restrictions is not enough for this scenario? I assumed that would allow the user to install the APN file manually.

Marked SolutionPending Review
Hexnode Expert
18 hours ago Sep 28, 2026
Marked SolutionPending Review

That setting controls whether users can access the manual profile installation flow from the device UI. However, it does not guarantee that every manually downloaded profile can be installed successfully on a supervised, MDM-managed iPad.

For carrier APN profiles, it is better to treat the profile as a managed configuration and deploy it from Hexnode. That way, iOS receives it through the MDM channel instead of through the user-initiated profile installation workflow.

Regards,
Isabel Lora
Hexnode UEM

Save